VibePackr
Website menu
GOOGLE CLOUD MARKETPLACE / VM REVIEW
Documentation workbook · R1

Official review checklist

143 mapped review items with source, applicability, procedure and evidence request.

English review edition · Official sources checked 2026-10-04 · Product baseline reference: 0.1.0-r232

Find the item you are reviewing

Each item connects an official passage to a responsible owner, the conditions for using it and the evidence to retain. Open an item to see the full procedure. Record actual results separately in the blank workbook.

143 mapped items · no test results prefilled

How to read the labels

Explicit requirement
The source uses a mandatory requirement. It still needs applicability and evidence.
Conditional requirement
The requirement applies when its stated condition holds. An owner must record any non-applicability basis.
Recommendation
Google recommends this practice; it is not relabeled as a universal mandatory rule.
Official procedure
A documented review or preparation step. Follow the current supported route with the responsible operator.
Google activity
A Google-owned review, decision or documented platform behavior. Supplier evidence does not replace Google’s recorded outcome.

01 · Vendor, environment and image prerequisites

60 mapped items. A row’s presence records document coverage only.

VM-01Become an eligible Marketplace vendor
Conditional requirementOfficial source ↗Item link

Source locator: “sign up to become a vendor”

Applies when
A vendor new to Cloud Marketplace.
Responsible role
Vendor onboarding owner.
Before starting
Company onboarding details and authorized representative.
Procedure
Follow vendor onboarding and retain the enrollment disposition.
Expected observation
Vendor enrollment is established independently of product review or publication.
Keep as evidence
Enrollment confirmation and owner/date; keep private account details outside the public guide.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

Vendor onboarding

VM-02Complete onboarding validation for every listing
Explicit requirementOfficial source ↗Item link

Source locator: “For your first (and all subsequent) listings”

Applies when
Every VM Marketplace product.
Responsible role
Vendor onboarding owner.
Before starting
Exact listing identity and current onboarding form.
Procedure
Complete the Cloud Marketplace Onboarding Validation Form for this listing, including subsequent listings.
Expected observation
A submission record is bound to the exact listing; submission is not approval.
Keep as evidence
Form version, listing reference, submission date and Google response in the private handoff.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

VM-03Supply project information for Producer Portal access
Explicit requirementOfficial source ↗Item link

Source locator: “complete the Cloud Marketplace Project Info Form”

Applies when
Every VM Marketplace product.
Responsible role
Vendor onboarding owner.
Before starting
Project identities and the form supplied by the Marketplace team.
Procedure
Complete the Project Info Form; reconcile with SET-06 and SET-07 rather than creating duplicate submissions.
Expected observation
The project-information submission and Portal enablement are separately recorded.
Keep as evidence
Form receipt and subsequent Partner Engineer enablement confirmation.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

VM-04Review and meet open source policy
Explicit requirementOfficial source ↗Item link

Source locator: “comply with Cloud Marketplace open source policy”

Applies when
Every VM Marketplace product.
Responsible role
Open source compliance owner.
Before starting
Exact shipped artifact inventory and the linked current policy.
Procedure
Have the owner review the linked recommendations, restrictions and policy against the shipped product. Record unresolved obligations explicitly.
Expected observation
A release-specific compliance disposition is recorded with supporting notices and any required remediation.
Keep as evidence
Owner review, policy revision/date and approved distributable notices.

Current evidence note: Dependency check pending. The linked open source policy has not been exhaustively mapped by this five-page review.

Open source compliance

VM-05Run the delivered product on Compute Engine
Explicit requirementOfficial source ↗Item link

Source locator: “deploy software to, and run on, Compute Engine”

Applies when
Every VM Marketplace product.
Responsible role
Deployment package owner.
Before starting
Exact VM product and supported deployment configuration.
Procedure
Verify that the Marketplace delivery deploys its software to Compute Engine and runs there.
Expected observation
The identified deployment is an operating Compute Engine VM product.
Keep as evidence
Deployment identity, product process/service observations and scoped test result.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

VM-06Use the Marketplace image and attached license
Explicit requirementOfficial source ↗Item link

Source locator: “Cloud Marketplace-hosted image with the attached Compute Engine license”

Applies when
Every VM Marketplace product.
Responsible role
Release owner.
Before starting
Candidate image, Marketplace delivery model and product license identity.
Procedure
Verify the Marketplace-hosted image and attached Compute Engine license for the exact submitted candidate. Resolve the hosting route with the Partner Engineer.
Expected observation
The delivered image and its valid license match the submitted product.
Keep as evidence
Image identity, Portal license reference and deployed-instance license evidence.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

VM-07Complete end-to-end testing before submission
Explicit requirementOfficial source ↗Item link

Source locator: “tested end to end before you submitted it”

Applies when
Every VM Marketplace product.
Responsible role
Deployment package owner.
Before starting
Exact delivery candidate and a customer-reproducible procedure.
Procedure
Complete the TEST mapping and retain the full customer path, including post-deployment setup, before claiming this requirement is met.
Expected observation
The exact submitted candidate has successful end-to-end evidence without unresolved required steps.
Keep as evidence
Candidate identity, run record, expected/actual results and unresolved-step register.

Current evidence note: Pending customer-delivery proof. r232 C7 customer administrator bootstrap remains blocked; local demonstrations do not close it.

VM testing

VM-08Resolve identified critical security issues
Conditional requirementOfficial source ↗Item link

Source locator: “any critical security issues related to the product”

Applies when
If the vendor or Google identifies critical product security issues.
Responsible role
Security response owner and release owner.
Before starting
Confirmed issue, affected release, remediation owner and separate repair/release authority.
Procedure
Track the issue to an authorized update and validation. Escalate any Frozen-release constraint to the owner; do not alter r232 through this guide.
Expected observation
A verified remediation disposition is available for the affected product.
Keep as evidence
Issue reference, affected version, authorized remediation, validation and release disposition.

Current evidence note: Conditional owner check pending. This mapping neither asserts a critical issue nor authorizes security repair.

VM-09Complete the environment and listing setup

Source locator: “Set up your Google Cloud environment”

Applies when
Every VM Marketplace product.
Responsible role
Vendor onboarding owner.
Before starting
Applicable SET rows and exact project/listing identities.
Procedure
Reconcile the setup rows with the real project and Producer Portal records.
Expected observation
Project setup and listing records have named owners and explicit dispositions.
Keep as evidence
Completed SET evidence references and pending items.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

Environment setup

VM-10Select and submit the pricing model

Source locator: “select a pricing model”

Applies when
Every VM Marketplace product.
Responsible role
Commercial pricing owner.
Before starting
Approved commercial model and current pricing documentation.
Procedure
Review the linked pricing options, select the model and record its Portal review result. The overview says review takes up to four business days and setup may continue in parallel.
Expected observation
An exact selected pricing model and its review disposition are recorded.
Keep as evidence
Approved pricing specification and dated Portal review status.

Current evidence note: Dependency check pending. Detailed pricing rules are outside the five-page mapping; the timing is guidance, not an approval guarantee.

Pricing models

VM-11Supply a reviewed VM image

Source locator: “Build your VM image”

Applies when
Every VM Marketplace product.
Responsible role
Release owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Reconcile the IMAGE requirements with the exact authorized release candidate and Partner Engineer feedback.
Expected observation
The candidate image has a traceable build and validation disposition.
Keep as evidence
Image identity and the completed IMAGE evidence references.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

Build a VM image

VM-12Review the complete deployment package requirements

Source locator: “Create your deployment package”

Applies when
Every VM Marketplace product.
Responsible role
Deployment package owner.
Before starting
Selected deployment method, image and current linked package documentation.
Procedure
Review the linked package requirements for the selected deployment method and supply the package-specific checklist and evidence.
Expected observation
The exact deployment package has its own complete requirements and review disposition.
Keep as evidence
Package identity, method-specific requirements review and Portal disposition.

Current evidence note: Dependency check pending. This guide does not claim complete coverage of the linked deployment-package documentation.

Deployment package

VM-13Track associated Google Cloud consumption

Source locator: “Add a label to track your product's associated consumption”

Applies when
Every VM Marketplace product.
Responsible role
Deployment package owner.
Before starting
Current consumption-tracking instructions and authorized package configuration.
Procedure
Have the package owner determine and validate the required consumption label against the linked instructions.
Expected observation
Required consumption labeling is present and verifiable in the applicable deployment.
Keep as evidence
Label requirement reference, package mapping and deployed observation.

Current evidence note: Dependency check pending. The deeper labeling specification is not fully mapped here; no cloud labeling operation was performed.

Associated consumption tracking

VM-14Reconcile the testing checklist

Source locator: “Test your product end-to-end”

Applies when
Every VM Marketplace product.
Responsible role
Deployment package owner.
Before starting
Exact release and complete TEST rows.
Procedure
Link all applicable TEST outcomes to the pre-submission end-to-end requirement in VM-07.
Expected observation
Testing coverage and unresolved outcomes are visible before submission.
Keep as evidence
TEST workbook and exact candidate binding.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

Product testing

VM-15Track every required product review

Source locator: “Submit your product to Cloud Marketplace”

Applies when
Every VM Marketplace product.
Responsible role
Producer Portal owner.
Before starting
Product Details, Pricing and Deployment Package submissions.
Procedure
Use the SUB mapping to track each submitted section, Google feedback and issue resolution.
Expected observation
Each required review has its own explicit Google disposition.
Keep as evidence
Dated Portal statuses and feedback-resolution records.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

Submitting a VM product

VM-16Separate approval from publication

Source locator: “After all reviews are approved”

Applies when
Every VM Marketplace product.
Responsible role
Producer Portal owner.
Before starting
All required review approvals and explicit publication authority.
Procedure
Record approval of all reviews before any publication decision. The overview describes launch within minutes after approval, not a guaranteed deadline.
Expected observation
Approval, publication action and public availability remain distinct recorded states.
Keep as evidence
Review approvals, publication authorization, action receipt and public listing observation.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

VM-17Assign post-launch maintenance and monitoring

Source locator: “Maintain and monitor your product after it has launched”

Applies when
Every VM Marketplace product.
Responsible role
Product operations and release owners.
Before starting
Support/maintenance ownership and current linked monitoring guidance.
Procedure
Review the linked monitoring guidance and record maintenance, monitoring and response responsibilities for the released product.
Expected observation
Post-launch responsibilities and observable operating records are defined.
Keep as evidence
Maintenance plan, monitoring references, response owner and review cadence.

Current evidence note: Dependency check pending. The linked monitoring documentation is not fully mapped by this review.

Monitoring guidance

VM-18Route onboarding questions to Partner Support Desk

Source locator: “include the word "Marketplace" in your description”

Applies when
When onboarding questions require Google assistance.
Responsible role
Vendor onboarding owner.
Before starting
Exact unresolved question and non-secret product/project reference.
Procedure
Submit an authorized Partner Support Desk request with Marketplace in the description and record the response.
Expected observation
The request is routed with enough context for Google to answer.
Keep as evidence
Private support reference, question, owner and response.

Current evidence note: No support message is sent by this documentation task.

Marketplace support

SET-01Separate development and public-image projects

Source locator: “you create two Google Cloud projects”

Applies when
Every VM Marketplace product.
Responsible role
Vendor onboarding owner.
Before starting
Approved project naming and ownership.
Procedure
Verify the development/testing project uses PARTNER_NAME-dev and the final-image project uses PARTNER_NAME-public, or record Partner Engineer guidance for the actual arrangement.
Expected observation
The two project purposes and exact identities are unambiguous.
Keep as evidence
Private project-purpose mapping and any Google-confirmed variance.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-02Keep the public project dedicated to images

Source locator: “Don't use this public project for anything other than hosting”

Applies when
Every VM Marketplace product.
Responsible role
Vendor onboarding owner.
Before starting
Public-project identity and scoped inventory.
Procedure
Verify the public project is used only for final Compute Engine image hosting.
Expected observation
No unrelated use is included in the public-project inventory.
Keep as evidence
Dated scope review with private identifiers redacted from public material.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-03Verify the specified onboarding access

Source locator: “grant the Editor (roles/editor) and Service Management Admin”

Applies when
Every VM Marketplace product.
Responsible role
Authorized project IAM owner.
Before starting
Current official principal/role pairs and explicit IAM authority outside this guide.
Procedure
Have the IAM owner compare both projects with the official onboarding-principal Editor/Service Management Admin grants and producer-principal Config Editor grant. Record discrepancies without changing permissions here.
Expected observation
The exact official principal/role/project relationships have an owner-verified disposition.
Keep as evidence
Access review reference and dated disposition; no credentials or complete IAM export in the public workbook.

Current evidence note: Pending owner confirmation. This is a documentation check, not authority to grant or broaden access.

SET-04Verify Compute Engine API availability in both projects

Source locator: “For each project, enable the Compute Engine API”

Applies when
Every VM Marketplace product.
Responsible role
Vendor onboarding owner.
Before starting
Exact development and public project identities.
Procedure
Record the Compute Engine API enablement disposition for each project.
Expected observation
Both projects meet the documented API prerequisite.
Keep as evidence
Dated API state observations for both projects.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-05Assign the public-project security contact

Source locator: “In the public project only, set a security contact”

Applies when
Every VM Marketplace product.
Responsible role
Security contact owner.
Before starting
Approved security contact and exact public-project identity.
Procedure
Verify the public project has the required security notification contact.
Expected observation
Security notifications have an assigned, current recipient.
Keep as evidence
Private contact configuration confirmation and review date.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-06Complete the Project Info Form once

Source locator: “You only need to complete this form once”

Applies when
Every VM Marketplace product.
Responsible role
Vendor onboarding owner.
Before starting
Projects configured and high-level product details available.
Procedure
Provide project/product details through the Project Info Form and link its existing receipt to VM-03; distinguish this one-time form from per-listing onboarding validation.
Expected observation
One traceable project-information submission supports Portal onboarding.
Keep as evidence
Form receipt, scope and owner/date.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-07Confirm Producer Portal enablement

Source locator: “Your Partner Engineer enables it for you”

Applies when
Every VM Marketplace product.
Responsible role
Partner Engineer and vendor onboarding owner.
Before starting
Completed Project Info Form.
Procedure
Obtain the Partner Engineer enablement disposition and verify authorized access to the intended product project.
Expected observation
Portal access is established for the intended project.
Keep as evidence
Enablement confirmation and access observation without credentials.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-08Prepare the three Portal review tracks

Source locator: “you submit the following information for review”

Applies when
Every VM Marketplace product.
Responsible role
Producer Portal owner.
Before starting
Exact product entry and named commercial/deployment owners.
Procedure
Prepare Product Details, Pricing and Deployment Package as separately tracked review sections.
Expected observation
All three tracks have identified inputs, owners and dispositions.
Keep as evidence
Three-track review register linked to the SUB rows.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-09Plan independent review tracks early

Source locator: “at any time and in any order”

Applies when
Every VM Marketplace product.
Responsible role
Producer Portal owner.
Before starting
The three review requirements and submission schedule.
Procedure
Plan the reviews independently: the official page permits any order and says some reviews may take up to two weeks. Start reviewing requirements early.
Expected observation
The schedule separates estimated review durations from actual approval dates.
Keep as evidence
Owner schedule and actual dated Portal statuses.

Current evidence note: Official timing is an estimate, not a service-level guarantee or approval.

SET-10Establish the product entry before other reviews

Source locator: “you only need to create a Cloud Marketplace entry”

Applies when
Every VM Marketplace product.
Responsible role
Producer Portal owner.
Before starting
Producer Portal access and chosen public project.
Procedure
Confirm the product entry exists in the intended public project; complete remaining details as the separately tracked reviews progress.
Expected observation
A stable product entry anchors all review records.
Keep as evidence
Product entry reference, project binding and owner.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-11Resolve Portal access through the documented route
Conditional requirementOfficial source ↗Item link

Source locator: “If you don't see the link, or can't access the URL”

Applies when
If the Producer Portal URL or link is unavailable.
Responsible role
Producer Portal owner.
Before starting
Intended project, authorized role review and exact access error.
Procedure
Verify the selected project and required Editor role with the IAM owner. If access remains unavailable, use Partner Support Desk and include Marketplace in the description.
Expected observation
The access issue has a supported resolution or explicit support disposition.
Keep as evidence
Error, project/role confirmation and private support reference.

Current evidence note: No access expansion or support request is executed here.

Marketplace support

SET-12Confirm the VM product type

Source locator: “Select Virtual machine”

Applies when
Every VM Marketplace product.
Responsible role
Producer Portal owner.
Before starting
Approved product definition before entry creation.
Procedure
Verify the product entry is of type Virtual machine. Record the intended product name and Product ID.
Expected observation
The product type matches the VM review being prepared.
Keep as evidence
Product type/name/ID confirmation in the private handoff.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-13Verify immutable product identity before creation

Source locator: “The Product ID and product type cannot be changed”

Applies when
Every VM Marketplace product.
Responsible role
Producer Portal owner.
Before starting
Approved product ID and type.
Procedure
Confirm the ID and type before creation because both become immutable; confirm the product name before submission, when it can still be changed.
Expected observation
The listing URL identity and product type are deliberately chosen and recorded.
Keep as evidence
Owner-confirmed identity decision and current product-entry record.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-14Complete core listing information

Source locator: “Enter a name, tagline, image, and overview description”

Applies when
Every VM Marketplace product.
Responsible role
Product listing owner.
Before starting
Approved public product description and image assets.
Procedure
In Product Details, complete name, tagline, image and overview description, then check that public claims match the delivered product.
Expected observation
The listing contains accurate, reviewable public product information.
Keep as evidence
Submitted listing text/assets and owner review.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-15Select at most two listing categories

Source locator: “You can select up to two Category IDs”

Applies when
Every VM Marketplace product.
Responsible role
Product listing owner.
Before starting
Applicable Portal category options.
Procedure
Choose the relevant Category IDs within the documented limit of two.
Expected observation
The categories are relevant and within the allowed count.
Keep as evidence
Selected category IDs and product relevance rationale.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-16Complete documentation and product metadata

Source locator: “Complete the Documentation and Product metadata sections”

Applies when
Every VM Marketplace product.
Responsible role
Product listing and documentation owners.
Before starting
Current public guide URLs and exact product metadata.
Procedure
Complete the Documentation and Product metadata sections and verify the listed documentation links.
Expected observation
Reviewers can reach current documentation from the listing.
Keep as evidence
Submitted documentation URLs, metadata and link-check result.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-17Use directly relevant search keywords
Explicit requirementOfficial source ↗Item link

Source locator: “They must be directly relevant to your product”

Applies when
Every VM Marketplace product.
Responsible role
Product listing owner.
Before starting
Proposed Search keywords field.
Procedure
Check each search keyword for direct relevance to the product.
Expected observation
All submitted search keywords are directly relevant.
Keep as evidence
Keyword list and relevance review.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-18Exclude competitor-licensed names from keywords
Explicit requirementOfficial source ↗Item link

Source locator: “must not include brand names or product names licensed by competitors”

Applies when
Every VM Marketplace product.
Responsible role
Product listing owner.
Before starting
Proposed search keyword list.
Procedure
Review the keywords against the prohibition on brand/product names licensed by competitors.
Expected observation
The submitted keyword field avoids the prohibited names.
Keep as evidence
Owner-reviewed keyword list.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-19Resolve additional or unavailable categories
Conditional requirementOfficial source ↗Item link

Source locator: “might require additional approvals for some categories”

Applies when
If a selected category needs extra approval or is not listed in Producer Portal.
Responsible role
Producer Portal owner.
Before starting
Category choice and Google category-specific instructions.
Procedure
Record required extra approvals; request an unlisted category through the special category request form supplied by Google.
Expected observation
Category-specific approvals or request outcomes are explicit.
Keep as evidence
Category request and approval disposition in private handoff.

Current evidence note: Pending exact product and delivery evidence. This row records what to verify, not a completed check.

SET-20Track actual Product Details review status

Source locator: “approximately 2-5 business days”

Applies when
Every VM Marketplace product.
Responsible role
Producer Portal owner.
Before starting
Product Details review submission.
Procedure
Track the actual review response; the page estimates approximately 2–5 business days for Partner Engineering review and approval.
Expected observation
Actual Google status and dates, rather than elapsed time, determine the recorded disposition.
Keep as evidence
Submission date and actual review response.

Current evidence note: The estimate does not establish approval or a guaranteed turnaround.

IMG-01Use development-first image review

Source locator: “move it to your public project after your Google Partner Engineer has verified”

Applies when
Every VM Marketplace product.
Responsible role
Release owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Record image development in the development project, Partner Engineer verification, and only then the separately authorized public-image progression.
Expected observation
Development, Engineer verification and public-image progression are traceable distinct steps.
Keep as evidence
Image identities and dated Partner Engineer disposition.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

IMG-02Identify the required Google Cloud tooling

Source locator: “Download the Google Cloud SDK”

Applies when
Every VM Marketplace product.
Responsible role
Release owner.
Before starting
Approved isolated image-authoring environment.
Procedure
Record the Google Cloud SDK/tooling availability and version for the authorized image workflow.
Expected observation
The image workflow has the required tooling identified.
Keep as evidence
Tool/version observation and build-environment identity.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

IMG-03Use a supported base image and declare architectures

Source locator: “Use one of Google's supported base public images”

Applies when
Every VM Marketplace product.
Responsible role
Release owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Verify the supported Google base public image, installed app packages/configuration, and each offered Arm or x86 image/machine-type pairing. Multiple architecture images may share one product.
Expected observation
Every offered architecture has an identified supported base and compatible machine scope.
Keep as evidence
Base image and package inventory; architecture/machine matrix.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

IMG-04Review supported app-credential retrieval
Conditional requirementOfficial source ↗Item link

Source locator: “If you intend to provide support to your customers”

Applies when
If customer support is provided under the image instructions.
Responsible role
Customer support and deployment owners.
Before starting
Approved credential lifecycle and supported customer access design.
Procedure
Have the owners review the official instruction to install app-user-credential retrieval scripts and bind it to the supported design. Do not expose credential values in documentation evidence.
Expected observation
A supported retrieval path or Partner Engineer-confirmed applicability disposition is recorded.
Keep as evidence
Approved procedure, applicability decision and redacted validation.

Current evidence note: Pending exact delivery design/evidence. This guide does not authorize secret retrieval or resolve C7 bootstrap.

IMG-05Identify the licensed-image preparation inputs

Source locator: “Install and customize your software”

Applies when
Every VM Marketplace product.
Responsible role
Release owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Record the target project/zone, primary instance, software configuration and required startup scripts for an authorized image build. The source procedure includes a primary instance with cloud-platform scope; applicability and authority must be reviewed before any future execution.
Expected observation
The exact authorized build inputs and startup behavior are reproducible.
Keep as evidence
Private build specification, scoped authority and startup-script validation.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

IMG-06Bind login setup to deployment metadata
Conditional requirementOfficial source ↗Item link

Source locator: “your app must be customized through a server script”

Applies when
If the app has a dashboard, database or management console requiring login.
Responsible role
Deployment package owner.
Before starting
Approved supported login design and the exact deployment package.
Procedure
Verify the required server script reads login credentials from instance metadata and configures the username/password during deployment; obtain Partner Engineer guidance where the product uses a different supported model.
Expected observation
The applicable login-provisioning behavior is demonstrated for the customer delivery candidate.
Keep as evidence
Applicability decision, package/script binding and redacted fresh-deployment test.

Current evidence note: Pending customer-delivery proof. Local admin access does not prove the supported r232 customer bootstrap path.

IMG-07Exclude build-user data and SSH keys from the image
Explicit requirementOfficial source ↗Item link

Source locator: “you must clean the input disk”

Applies when
Every VM Marketplace product.
Responsible role
Release owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Review the input disk for build-user directories, SSH keys and temporary installation files before an authorized new image is made. Do not treat deletion of the Frozen disk as a cleanup option.
Expected observation
The customer image does not inherit unwanted build-user data or credentials.
Keep as evidence
Redacted image-hygiene review and exact candidate identity.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

IMG-08Review the disk-preserving cleanup procedure

Source locator: “Delete the VM while preserving the disk”

Applies when
For a separately authorized future image build following this official cleanup method.
Responsible role
Release owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Review the documented sequence: retain the source disk, use an isolated helper instance with the disk attached as data, clean the mounted disk, and retain the updated disk when the helper is removed. Require exact resource and cleanup authority before execution.
Expected observation
An authorized procedure preserves the intended disk throughout cleanup and image creation.
Keep as evidence
Approved resource disposition and bounded build/cleanup receipt.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

IMG-09Bind the image to its Portal VM license

Source locator: “Under VM license, note the name”

Applies when
Every VM Marketplace product.
Responsible role
Release owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Obtain the exact product VM license from the Deployment Package section and bind that license to the image-creation specification.
Expected observation
The image specification uses the exact license assigned to the product.
Keep as evidence
Portal license reference, image specification and deployed license result.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

IMG-10Use architecture-aware, unique image names
Explicit requirementOfficial source ↗Item link

Source locator: “who-vmOS-image-architecture-date”

Applies when
Every VM Marketplace product.
Responsible role
Release owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Check the image name follows the documented who-vmOS-image-architecture-date form with Arm or x86_64, and uses a new unique name for each update.
Expected observation
Each release image can be distinguished by its immutable identity and supported architecture.
Keep as evidence
Image naming record and version/architecture mapping.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

IMG-11Verify image-build project roles and disk identity

Source locator: “roles/compute.storageAdmin”

Applies when
Every VM Marketplace product.
Responsible role
Authorized IAM and release owners.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Have the owners check the documented public-project Compute Storage Admin and development-project Compute Image User roles, plus source disk project/zone/name and product license. An image description is optional.
Expected observation
The planned operation has exact resource inputs and an explicit role/authority disposition.
Keep as evidence
Private role review and image input manifest with optional description disposition.

Current evidence note: Pending owner confirmation; this row does not grant IAM permissions, change image access or authorize a build.

IMG-12Apply public-image access only where required
Conditional requirementOfficial source ↗Item link

Source locator: “For non-Terraform products that don't use Marketplace owned images”

Applies when
Non-Terraform products that do not use Marketplace-owned images. Terraform-only deployment or Marketplace-owned images are excluded by the source note.
Responsible role
Deployment owner, IAM owner and Partner Engineer.
Before starting
Confirmed deployment method, image ownership model and exact access authority.
Procedure
Determine applicability first. Where applicable, have the authorized owner review the official public-image availability instruction without applying access changes through this guide.
Expected observation
The conditional access requirement has a justified, Partner Engineer-confirmed disposition; actual access evidence is attached only if applicable.
Keep as evidence
Deployment/ownership classification, applicability rationale and private access-review evidence.

Current evidence note: Applicability is pending; do not label this not applicable solely because an image is Frozen. No public-access grant is authorized.

IMG-13Review direct-package random password support

Source locator: “single VM instance with basic firewall rules”

Applies when
A simple single-VM deployment with basic firewall rules that needs a generated password.
Responsible role
Deployment package owner.
Before starting
Selected deployment method and approved login requirements.
Procedure
Review the documented direct deployment-package option for automatically including a secure randomized password. Link the decision to the login requirement and GS guidance.
Expected observation
The chosen credential-provisioning option is documented and can be validated on the exact candidate.
Keep as evidence
Package-method decision and redacted generation/retrieval proof.

Current evidence note: Conditional option, not proof that the current product uses or supports this path. Password values must remain private.

Deployment package

IMG-14Review the mpdev credential option

Source locator: “mpdev tool, which we recommend for most use cases”

Applies when
When choosing a deployment-package authoring method.
Responsible role
Deployment package owner.
Before starting
Deployment requirements and linked package documentation.
Procedure
Consider the official mpdev recommendation for most use cases, including automatic inclusion of multiple secure randomized passwords. Record the selected method and current Partner Engineer guidance.
Expected observation
The method choice and applicable credential behavior are explicit.
Keep as evidence
Method selection, Google guidance and redacted package validation.

Current evidence note: The linked deployment-package documentation remains an owner dependency; no current mpdev integration is inferred.

Deployment package

IMG-15Validate supported post-deployment password retrieval
Conditional requirementOfficial source ↗Item link

Source locator: “to obtain the values of any passwords that you created”

Applies when
If passwords are created by the selected metadata-based deployment flow.
Responsible role
Deployment package owner.
Before starting
Approved password name/binding and authorized customer retrieval procedure.
Procedure
Verify the documented within-VM metadata retrieval works for the approved customer path and document how the customer obtains credentials without publishing their values.
Expected observation
The intended customer can obtain the appropriate generated credentials through the approved path.
Keep as evidence
Redacted retrieval result tied to a fresh deployment and documented customer procedure.

Current evidence note: Pending exact delivery proof; no credential retrieval is executed by this documentation task.

IMG-16Validate a fresh instance from the candidate image

Source locator: “Create a VM instance with your newly created image”

Applies when
Every VM Marketplace product.
Responsible role
Deployment package owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Within separately authorized testing, create a fresh instance from the exact candidate image and verify product functionality.
Expected observation
Product functionality is observed on a newly deployed candidate, not inferred from a development machine.
Keep as evidence
Image/instance binding, functional test steps and actual results.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

IMG-17Inspect attached licenses on the test VM

Source locator: “verify that valid licenses are attached”

Applies when
Every VM Marketplace product.
Responsible role
Deployment package owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Use the authorized instance inspection path to verify valid attached licenses and compare them with the product license record.
Expected observation
The actual deployed VM exposes the expected valid product license.
Keep as evidence
Redacted instance license observation and product/image identity binding.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

IMG-18Resolve the documented Python baseline

Source locator: “Verify that Python 2.6 or greater is installed”

Applies when
Every VM Marketplace product.
Responsible role
Partner Engineer and release owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Record the official wording "Python 2.6 or greater" and obtain current applicability guidance for the selected OS/image. Preserve the observed version; do not install obsolete software to satisfy this wording.
Expected observation
Current Google applicability guidance and the exact candidate observation are reconciled.
Keep as evidence
Dated Partner Engineer guidance and redacted version observation.

Current evidence note: Official wording retained; applicability pending. Frozen r232 is not modified. Any future image change needs separate release authority.

IMG-19Resolve the documented tooling and service checks

Source locator: “Verify that the following packages are installed”

Applies when
Every VM Marketplace product.
Responsible role
Partner Engineer and release owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Record the source checks for gcloud, SSH client, sshd, curl and DHCP, then obtain current applicability guidance for the selected OS/image and record actual observations. Do not equate a process-name search with functional readiness.
Expected observation
Every listed check has a current applicability decision and scoped evidence.
Keep as evidence
Five-item applicability/observation record and dated Partner Engineer guidance.

Current evidence note: Official checks are retained as written requirements to reconcile; no package installation or Frozen-image modification is authorized.

IMG-20Inspect residual users and credentials on the test image

Source locator: “no other user directories installed on the instance except for your own”

Applies when
Every VM Marketplace product.
Responsible role
Release owner.
Before starting
Exact candidate image, project and release identities; authorized isolated build or test scope.
Procedure
Check the deployed test instance for unintended user directories and residual credentials, preserving the source allowance for the test operator's own directory. Review findings without exposing secret contents.
Expected observation
No unintended build-user directories or credentials are inherited by the customer image.
Keep as evidence
Redacted hygiene inspection tied to the candidate image.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

IMG-21Resolve the documented monthly image refresh

Source locator: “re-build and re-publish images once every month”

Applies when
Every VM Marketplace product.
Responsible role
Partner Engineer and release owner.
Before starting
Frozen release constraints, base-image update policy and separately authorized future release plan.
Procedure
Record the official monthly rebuild/republication instruction when Google updates base public images. Obtain current applicability guidance and an owner-approved future release plan; never rebuild or republish Frozen r232 through this guide.
Expected observation
The maintenance obligation, current Google guidance and future-release authority are reconciled explicitly.
Keep as evidence
Dated Google guidance, maintenance owner and separate future-release decision.

Current evidence note: Official wording retained; maintenance applicability/plan pending. This instruction does not thaw Frozen r232.

IMG-22Consider the optional image-build automation tool

Source locator: “consider using the open source tool Imagebuilder”

Applies when
If automating future authorized VM image builds.
Responsible role
Release owner.
Before starting
Approved future build scope and chosen toolchain.
Procedure
Consider the Imagebuilder option cited by Google and record the chosen approach; adopting it is not a required product change.
Expected observation
Automation choice is documented without implying use or validation of Imagebuilder.
Keep as evidence
Owner tool-choice disposition and, only if adopted, scoped validation.

Current evidence note: Pending release-specific evidence. Frozen r232 must remain unchanged; any new build, cleanup or release requires separate authority.

02 · Customer Getting Started documentation

16 mapped items. A row’s presence records document coverage only.

GS-01Maintain a Google Cloud Getting Started page
Explicit requirementOfficial source ↗Item link

Source locator: “Every product must be accompanied by a Google Cloud-specific Getting Started document”

Applies when
Every VM product.
Responsible role
VibePackr documentation owner
Before starting
Identify the exact proposed VM delivery and the vendor documentation owner.
Procedure
Check that a vendor-maintained website page gives detailed Google Cloud deployment and configuration steps for that delivery.
Expected observation
A reachable, maintained Google Cloud-specific page identifies its applicable delivery and owner.
Keep as evidence
Public URL, page revision or capture date, delivery identity and owner.

Current evidence note: A public deployment guide exists. Its availability does not prove end-to-end reproducibility for the exact Marketplace review delivery.

Related VibePackr guidance

GS-02Consider permitted Google Cloud co-branding

Source locator: “We suggest that you co-brand the page with the Google Cloud logo”

Applies when
Every VM product.
Responsible role
VibePackr documentation owner
Before starting
An owner decides whether co-branding is appropriate and confirms permitted brand assets.
Procedure
Record whether the Getting Started page will use the Google Cloud logo from Partner Network Hub; note that Hub access requires registration.
Expected observation
The optional branding choice and asset source are recorded; absence is not classified as failure of a mandatory requirement.
Keep as evidence
Branding decision and asset reference, if used.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

GS-03Describe the complete customer journey

Source locator: “starting with the product listing page on Cloud Marketplace”

Applies when
Every VM product.
Responsible role
VibePackr documentation owner
Before starting
The listing entry, deployment package and post-deployment procedure are identified.
Procedure
Read the guide from the Marketplace listing through deployment, configuration and post-deployment maintenance; map each transition to the next customer action.
Expected observation
The customer can follow an ordered journey without an unexplained transition.
Keep as evidence
Reviewed page sections and a journey checklist identifying any missing transition.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

Related VibePackr guidance

GS-04Support the journey with screenshots

Source locator: “We recommend including screenshots throughout the document”

Applies when
Every VM product.
Responsible role
VibePackr documentation owner
Before starting
Screenshots are tied to an identified delivery and contain no sensitive information.
Procedure
Check that important deployment and operation steps have relevant screenshots alongside text; mark local demonstrations with their actual scope.
Expected observation
Screenshots show the action and resulting state without implying an untested Marketplace result.
Keep as evidence
Captioned screenshot inventory with delivery identity and capture context.

Current evidence note: Published walkthroughs include local evidence. Local R234 or repaired Admin candidate screenshots are not proof of the frozen r232 Marketplace customer path.

Related VibePackr guidance

GS-05Explain machine configuration inputs

Source locator: “The recommended machine configuration, disk sizes, and zones.”

Applies when
Every VM product.
Responsible role
VibePackr documentation owner
Before starting
Delivery-specific defaults, recommendations and supported choices are supplied by the product owner.
Procedure
Check that the guide identifies recommended machine type, CPU and memory and distinguishes a reference estimate from a minimum requirement.
Expected observation
The customer can choose the input with its purpose and scope understood.
Keep as evidence
Page section, input/default inventory and product-owner confirmation for the exact delivery.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

Related VibePackr guidance

GS-06Explain disk sizing inputs

Source locator: “The recommended machine configuration, disk sizes, and zones.”

Applies when
Every VM product.
Responsible role
VibePackr documentation owner
Before starting
Delivery-specific defaults, recommendations and supported choices are supplied by the product owner.
Procedure
Check that the guide identifies boot and additional disk sizes and their roles and distinguishes a reference estimate from a minimum requirement.
Expected observation
The customer can choose the input with its purpose and scope understood.
Keep as evidence
Page section, input/default inventory and product-owner confirmation for the exact delivery.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

Related VibePackr guidance

GS-07Explain location inputs

Source locator: “The recommended machine configuration, disk sizes, and zones.”

Applies when
Every VM product.
Responsible role
VibePackr documentation owner
Before starting
Delivery-specific defaults, recommendations and supported choices are supplied by the product owner.
Procedure
Check that the guide identifies recommended deployment zones and relevant regional assumptions and distinguishes a reference estimate from a minimum requirement.
Expected observation
The customer can choose the input with its purpose and scope understood.
Keep as evidence
Page section, input/default inventory and product-owner confirmation for the exact delivery.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

Related VibePackr guidance

GS-08Explain required ports

Source locator: “If the customer has to open any ports (particularly 80 or 443).”

Applies when
Every VM product.
Responsible role
VibePackr documentation owner
Before starting
The product owner supplies the exact delivery network requirements.
Procedure
List whether the customer must open ports, particularly HTTP 80 or HTTPS 443; explain the required purpose and scope without assuming either port is necessary.
Expected observation
The guide identifies required ports and distinguishes optional or unnecessary exposure.
Keep as evidence
Network requirements table and guide section tied to the delivery.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

Related VibePackr guidance

GS-09Explain port defaults and customer actions

Source locator: “Whether the required ports are opened by default”

Applies when
Every VM product.
Responsible role
VibePackr documentation owner
Before starting
The required-port inventory and deployment defaults are known.
Procedure
For each required port, state whether deployment opens it by default or the customer must select an authorized deployment option.
Expected observation
The customer knows which action is required and can compare the deployed state with the documented default.
Keep as evidence
Per-port default/action table and corresponding deployment UI reference.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

Related VibePackr guidance

GS-10List additional configuration commands

Source locator: “The document should list any additional commands needed to configure the product.”

Applies when
Every VM product.
Responsible role
VibePackr documentation owner
Before starting
A delivery-specific, supported configuration procedure has been identified.
Procedure
Check that every additional configuration command needed after deployment is listed with prerequisites, input placeholders, expected output and the point at which to stop.
Expected observation
The customer can identify all required configuration steps without inventing commands or substituting internal procedures.
Keep as evidence
Command inventory and corresponding guide sections; explicitly justified absence if none are needed.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

Related VibePackr guidance

GS-11Explain administrator access

Source locator: “If your product requires a login”

Applies when
When the product requires a login.
Responsible role
VibePackr documentation owner
Before starting
The supported customer administrator access route is defined for the delivery.
Procedure
Explain whether and how the customer reaches an administrator page or console URL, including the supported access route and prerequisites.
Expected observation
A first customer can identify the intended admin entry point; an unresolved bootstrap path is explicitly marked as pending.
Keep as evidence
Admin access section and delivery-specific first-customer access result when authorized testing occurs.

Current evidence note: The published guide describes C7 as pending. A local Admin connection demonstration does not close the frozen r232 first-customer bootstrap gap.

Related VibePackr guidance

GS-12Explain how login credentials are obtained

Source locator: “how login credentials can be obtained.”

Applies when
When the product requires a login.
Responsible role
VibePackr documentation owner
Before starting
The product owner provides the supported first-customer credential provisioning route.
Procedure
Document where and how the authorized customer obtains credentials and which party is responsible; do not publish secret values or substitute internal test credentials.
Expected observation
The guide gives a usable, supported acquisition route or explicitly records the unresolved owner input.
Keep as evidence
Credential acquisition instructions and redacted first-customer verification record when available.

Current evidence note: C7 remains a declared first-customer gap for frozen r232. This checklist does not approve a new credential or bootstrap design.

Related VibePackr guidance

GS-13Verify generated administrator passwords
Conditional requirementOfficial source ↗Item link

Source locator: “the password must be auto-generated.”

Applies when
Only if a password is required to access an administrator page or console.
Responsible role
VibePackr documentation owner
Before starting
The product owner has confirmed that this password condition applies to the delivery.
Procedure
Record how the delivery meets the auto-generated-password requirement and request redacted evidence from the approved credential flow. If no password is used, record the reason for that applicability decision.
Expected observation
Any required administrator password is auto-generated; the applicability decision is supported.
Keep as evidence
Applicability rationale and redacted provisioning evidence, without the password itself.

Current evidence note: Conditional Google requirement. It does not prescribe VibePackr password authentication or authorize a new authentication design.

Related VibePackr guidance

GS-14Document SSH access

Source locator: “Can connect to the VM instance using SSH.”

Applies when
Every VM product.
Responsible role
VibePackr documentation owner
Before starting
A supported customer SSH access route and prerequisites are identified.
Procedure
Check that the Getting Started page explains how the customer reaches the VM through the supported SSH route and recognizes connection failure.
Expected observation
The customer can follow a clear SSH access procedure for the exact delivery.
Keep as evidence
SSH guide section and separately recorded authorized connection result.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

Related VibePackr guidance

GS-15Document application health checks

Source locator: “Can check the status or health of the app.”

Applies when
Every VM product.
Responsible role
VibePackr documentation owner
Before starting
Supported readiness and health observations are identified for the delivery.
Procedure
Check that the guide explains how to observe application status or health and distinguishes a running process from a ready, connected product.
Expected observation
The customer can identify a healthy state, an incomplete state and the next supported action.
Keep as evidence
Health guide section, expected observations and authorized delivery-specific results.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

Related VibePackr guidance

GS-16Submit the draft URL for Partner Engineer feedback

Source locator: “email the URL of your draft to your assigned Partner Engineer for review and feedback.”

Applies when
Every VM product.
Responsible role
VibePackr review coordinator
Before starting
The Getting Started draft is reviewed and its assigned Partner Engineer is known.
Procedure
Have the authorized review coordinator send the draft URL to the assigned Partner Engineer and track feedback against the same document revision. This checklist does not send a message.
Expected observation
The assigned Partner Engineer receives the intended draft; feedback and its disposition can be traced.
Keep as evidence
Private correspondence reference, sent URL/revision, date and feedback log.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

03 · Preview and review access

15 mapped items. A row’s presence records document coverage only.

TEST-01Plan a customer-view preview

Source locator: “preview and test the product.”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
Identify the product, image and deployment package versions under review.
Procedure
Include a preview of the listing and deployment experience in the review plan, using the customer-facing flow.
Expected observation
The planned preview identifies the exact delivery and what the customer will see.
Keep as evidence
Preview plan and exact product/image/package identity.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-02Confirm the uploaded deployment object
Explicit requirementOfficial source ↗Item link

Source locator: “the Cloud Storage object must be uploaded and validated in Producer Portal.”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
The authorized package owner supplies the intended Cloud Storage object identity.
Procedure
Before scheduling deployment preview, request evidence that the correct Cloud Storage object was uploaded and selected in Producer Portal.
Expected observation
The uploaded object identity matches the intended deployment package.
Keep as evidence
Private object identity, package digest/version and portal upload record.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-03Confirm successful package validation
Explicit requirementOfficial source ↗Item link

Source locator: “the Cloud Storage object must be uploaded and validated in Producer Portal.”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
The intended Cloud Storage object has an upload record.
Procedure
Check the portal record for successful validation of that exact uploaded object before marking preview prerequisites satisfied.
Expected observation
Producer Portal reports successful validation for the intended package revision.
Keep as evidence
Portal validation state, timestamp and matching object/package identity.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-04Confirm the preview project and authorized portal access

Source locator: “verify that you've selected the correct project and have the Editor (roles/editor) role for the project.”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
The public project ID and authorized review operator are identified.
Procedure
Document the Producer Portal entry for the public project. If access is unavailable, have the account owner verify the selected project and required Editor role before proceeding; this row does not grant access.
Expected observation
The authorized operator can reach the correct product project in Producer Portal.
Keep as evidence
Redacted project selector/access confirmation and operator identity.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-05Open the selected product deployment package

Source locator: “On the Overview page, click Deployment package.”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
Portal access and the product identity are confirmed.
Procedure
In the planned preview procedure, select the named product and open Deployment package from its Overview page.
Expected observation
The package page belongs to the intended product and version.
Keep as evidence
Redacted product overview and package identity capture.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-06Enter deployment preview after validation

Source locator: “Verify that your deployment package was read and validated successfully and click Deployment preview.”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
The exact package was read and validated successfully.
Procedure
Include a gate that checks the successful read/validation state before the operator selects Deployment preview.
Expected observation
The preview opens for the same successfully validated package.
Keep as evidence
Portal read/validation state and preview identity.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-07Review preview settings before deployment

Source locator: “Review the deployment details and click Deploy.”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
Preview prerequisites and a separately authorized test scope are recorded.
Procedure
Plan to review the deployment details before the authorized operator selects Deploy; retain the selected settings and resulting deployment identity.
Expected observation
The resulting preview uses the reviewed settings and has an observable deployment outcome.
Keep as evidence
Settings capture, deployment identity and outcome.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-08Verify behavior before leaving the preview

Source locator: “verified that it behaves as you expect”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
A preview deployment completed and its expected behavior is written down.
Procedure
Plan a comparison of observed behavior with the stated expectations before exiting the preview; record discrepancies rather than assuming deployment success proves behavior.
Expected observation
Observed results are linked to expected product behavior and all discrepancies are retained.
Keep as evidence
Behavior checklist, observations and discrepancy log for the preview deployment.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-09Record the Marketplace-owned image distinction

Source locator: “Cloud Marketplace uses your original version of the VM image for your testing.”

Applies when
When Use Marketplace owned images is enabled.
Responsible role
VibePackr test owner
Before starting
The image ownership setting and original image identity are known.
Procedure
Record that the vendor preview tests the original image while customers access a Google-owned copy; keep those identities distinct in the evidence.
Expected observation
Preview proof is explicitly scoped to the original image; customer-copy equivalence is not silently assumed.
Keep as evidence
Ownership setting, original image identity and any separately supplied customer-copy correspondence.

Current evidence note: The official test page explicitly distinguishes the two image paths. The exact setting for this review delivery remains owner input.

TEST-10Agree a current supported preview teardown procedure

Source locator: “To delete the preview deployment, open the Deployment Manager page and delete the deployment.”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
The test owner identifies preview resources and obtains the current Partner Engineer-supported teardown route.
Procedure
Record cleanup ownership, retained evidence and the supported teardown procedure before testing. The source names the legacy Deployment Manager deletion route; confirm the current route with the Partner Engineer instead of treating that text as a live deletion instruction.
Expected observation
The preview has an approved, current cleanup plan and its completion can be recorded without changing retained product artifacts.
Keep as evidence
Partner Engineer clarification, resource inventory, authorized cleanup procedure and later cleanup result.

Current evidence note: Legacy reference retained for traceability only. No deployment or deletion is executed by this guide.

TEST-11Plan every product end-to-end flow

Source locator: “We recommend you test each of your products' end-to-end flows”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
The product owner lists supported customer flows and their expected outcomes.
Procedure
Prepare a test matrix for each end-to-end flow, connecting listing entry, deployment, configuration, use and completion to an exact delivery.
Expected observation
No supported flow is silently omitted; exclusions have an owner and rationale.
Keep as evidence
Flow inventory, delivery-bound test matrix and exclusions with rationale.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

Related VibePackr guidance

TEST-12Obtain Partner Engineer readiness for the prescribed tests

Source locator: “as soon as your Partner Engineer informs you that your product is ready for end-to-end testing.”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr review coordinator / Google Partner Engineer
Before starting
The assigned Partner Engineer and product delivery are identified.
Procedure
Record the Partner Engineer notification that the product is ready for the prescribed end-to-end testing before scheduling that test phase.
Expected observation
The test phase is tied to the Partner Engineer readiness notification.
Keep as evidence
Private notification reference, date, product identity and permitted test scope.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-13Verify access for every tester

Source locator: “verify that all testers have access to the product.”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
The intended tester roster is approved.
Procedure
Have the account owner confirm product access for every named tester before test execution; record unavailable access as pending.
Expected observation
Each listed tester can access the product under the intended account.
Keep as evidence
Tester roster and redacted access confirmations; no credentials.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-14Verify development-project viewer access when needed
Conditional requirementOfficial source ↗Item link

Source locator: “If the product image(s) is not in your public project”

Applies when
When product images are outside the public project.
Responsible role
VibePackr test owner
Before starting
Image project placement and the intended tester roster are confirmed.
Procedure
Have the authorized project owner verify the documented viewer access for each tester in the development project containing the images. Record the access finding; do not create a grant from this checklist.
Expected observation
Every intended tester has the required access to the image-bearing development project, or the condition is justified as inapplicable.
Keep as evidence
Image-project identity, applicability rationale and redacted access confirmation.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-15Verify tester console and project membership
Explicit requirementOfficial source ↗Item link

Source locator: “The testers need to be users of Cloud console, and must be added to the project.”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
The authorized project owner has the tester roster.
Procedure
Request confirmation that each tester is a Cloud console user and has been added to the applicable project before testing.
Expected observation
The roster has no unconfirmed console user or project membership entry.
Keep as evidence
Redacted roster-to-project membership confirmation.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

04 · Listing, pricing, support and terms

12 mapped items. A row’s presence records document coverage only.

TEST-16Check Marketplace search visibility

Source locator: “Ensure that the product card is visible in the search results”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
The Partner Engineer-supported test visibility and tester access are confirmed.
Procedure
Plan to open Explore Marketplace, search for the product and record whether the intended product card appears.
Expected observation
The correct product card appears in the tester search results.
Keep as evidence
Search term, tester visibility context, date and result capture.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-17Check product card content

Source locator: “the information on the card is displayed correctly.”

Applies when
Each proposed VM product delivery.
Responsible role
VibePackr test owner
Before starting
The approved listing content and intended product identity are available.
Procedure
Compare the product card information with the intended listing content and record incorrect or clipped fields.
Expected observation
The card displays the intended product information correctly.
Keep as evidence
Card capture and field-by-field comparison to approved listing content.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-18Distinguish multiple product listings
Conditional requirementOfficial source ↗Item link

Source locator: “If you have more than one product”

Applies when
When the vendor has more than one product.
Responsible role
VibePackr test owner
Before starting
The relevant product listing inventory is known.
Procedure
Compare each product card and ensure its content can be distinguished from the vendor's other products.
Expected observation
Customers can tell the listed products apart; applicability is documented.
Keep as evidence
Product comparison captures or a documented single-product rationale.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-19Check the product details header

Source locator: “The header is displayed with your name, category, estimated costs and Launch button.”

Applies when
Each proposed VM product listing.
Responsible role
VibePackr test owner
Before starting
The intended listing and estimate are available.
Procedure
From the product card, open the product details page and check the name, category, estimated costs and Launch button in the header.
Expected observation
All four header elements are present and match the intended listing.
Keep as evidence
Header capture, listing revision and expected name/category/cost values.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-20Check description and Learn more destination

Source locator: “a Learn more link that points to a specific product or service page on your website.”

Applies when
Each proposed VM product listing.
Responsible role
VibePackr test owner
Before starting
The intended product description and specific vendor product page are known.
Procedure
Compare the displayed description and follow Learn more to verify that it reaches the specific product or service page.
Expected observation
The intended description is shown and Learn more resolves to the relevant product page.
Keep as evidence
Description capture, link URL and observed destination.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-21Check the technology stack fields

Source locator: “The tech stack is displayed, with the product type, version, last updated timestamp, and category ID and components, if applicable.”

Applies when
Each proposed VM product listing.
Responsible role
VibePackr test owner
Before starting
The exact release metadata and applicable components are supplied.
Procedure
Check product type, version, last updated timestamp, category ID and any applicable components in the displayed technology stack.
Expected observation
The fields are present, applicable and consistent with the delivery identity.
Keep as evidence
Technology-stack capture and comparison to delivery metadata; reasons for inapplicable components.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-22Check price breakdown and pricing links

Source locator: “The Pricing section has the price breakdown, as well as working links to pricing and free trial.”

Applies when
Each proposed VM product listing.
Responsible role
VibePackr test owner
Before starting
The approved pricing model and any trial offer are identified.
Procedure
Check the price breakdown and follow the pricing and free-trial links. If no trial is offered, retain the approved applicability decision rather than inventing an offer.
Expected observation
Pricing information is visible and applicable links work; trial treatment matches the approved offer.
Keep as evidence
Pricing capture, resolved links and trial applicability rationale.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-23Check pricing accuracy and expansion

Source locator: “The pricing details are correct, and the Show more arrow expands properly.”

Applies when
Each proposed VM product listing.
Responsible role
VibePackr test owner
Before starting
The approved price schedule and estimation assumptions are available.
Procedure
Compare displayed pricing details with the approved schedule and expand Show more to check hidden details.
Expected observation
Pricing values are accurate and Show more exposes the expected details.
Keep as evidence
Before/after expansion captures and price comparison.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-24Clarify whether support is included in price

Source locator: “clearly specifies whether the support is bundled into the pricing.”

Applies when
Each proposed VM product listing.
Responsible role
VibePackr test owner
Before starting
The approved support and commercial terms are available.
Procedure
Check that Maintenance & support explicitly states whether support is included in the listed price.
Expected observation
A customer can determine whether the listed price includes support.
Keep as evidence
Maintenance & support capture and approved inclusion statement.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-25Describe support channels and hours

Source locator: “A description of available support channels and their hours of service.”

Applies when
Each proposed VM product listing.
Responsible role
VibePackr test owner
Before starting
The approved support offer identifies channels and operating hours.
Procedure
Check that Maintenance & support describes each available channel and its hours of service without implying an unapproved service level.
Expected observation
Support channels and service hours are explicit and match the approved offer.
Keep as evidence
Support section capture and approved channel/hour reference.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-26Check the support-site link

Source locator: “A link to your support site.”

Applies when
Each proposed VM product listing.
Responsible role
VibePackr test owner
Before starting
The intended customer support entry point is known.
Procedure
Follow the link in Maintenance & support and verify that it reaches the intended customer support site.
Expected observation
The support link works and the customer can identify the support entry point.
Keep as evidence
Listed support URL and observed destination.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-27Check the EULA link

Source locator: “The Terms of service section includes a link to your End User License Agreement (EULA).”

Applies when
Each proposed VM product listing.
Responsible role
VibePackr test owner
Before starting
The legal owner supplies the applicable EULA and its approval state.
Procedure
Check that Terms of service links to the correct EULA and record its version and approval state; do not treat a public draft as an effective agreement.
Expected observation
The listing points to the intended EULA and unresolved legal approval is visible.
Keep as evidence
EULA link, version, observed destination and owner-provided approval reference.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

05 · Deployment and customer operations

14 mapped items. A row’s presence records document coverage only.

TEST-28Complete the launch inputs

Source locator: “Click Launch and fill in all of the applicable input fields to deploy the product.”

Applies when
Each proposed VM deployment package.
Responsible role
VibePackr test owner
Before starting
The approved test scope, deployment prerequisites and intended input values are recorded.
Procedure
Plan to open the product details page, select Launch and complete every applicable input; retain chosen values without secrets.
Expected observation
The deployment form accepts the applicable values and omitted fields have a documented reason.
Keep as evidence
Redacted completed-input inventory and form validation observations.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

Related VibePackr guidance

TEST-29Match deployment defaults to the pricing table

Source locator: “The product has the same default machine type and disk size as are specified in the pricing table”

Applies when
Each proposed VM deployment package.
Responsible role
VibePackr test owner
Before starting
The current listing pricing table and unchanged launch defaults are captured.
Procedure
Compare the default machine type and disk size in the launch form with those used in the product-details pricing table.
Expected observation
Both default values match the pricing-table configuration.
Keep as evidence
Side-by-side pricing table and launch defaults with listing/package revisions.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-30Check links in the deployment flow

Source locator: “Links work correctly.”

Applies when
Each proposed VM deployment package.
Responsible role
VibePackr test owner
Before starting
The relevant launch/deployment screens and intended destinations are identified.
Procedure
Follow each customer-facing link in the deployment flow and record its destination and any failure.
Expected observation
Each link reaches its intended accessible destination.
Keep as evidence
Link inventory with source screen, URL, destination and result.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-31Check HTTP and HTTPS deployment choices

Source locator: “HTTP and HTTPS ports are checked/unchecked accurately.”

Applies when
Each proposed VM deployment package.
Responsible role
VibePackr test owner
Before starting
Documented network requirements and deployment defaults are available.
Procedure
Compare HTTP and HTTPS checked/unchecked states in the deployment form with the documented requirements and defaults.
Expected observation
Both choices reflect the intended network configuration; neither is assumed necessary by this checklist.
Keep as evidence
Form capture and per-port comparison to documented requirements.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-32Verify deployment on the default machine type

Source locator: “Deploy the product on a default machine type, and verify that the product is deployed successfully.”

Applies when
Each proposed VM deployment package.
Responsible role
VibePackr test owner
Before starting
The test operator has a separately approved deployment scope and documented default settings.
Procedure
Include one default-machine deployment in the test plan and record its actual completion or failure before further checks.
Expected observation
The intended product deploys successfully using the documented default machine type.
Keep as evidence
Deployment identity, selected machine/disk settings, image/package identity and observed result.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-33Verify SSH connectivity to the deployed VM

Source locator: “You can SSH into the virtual machine instance.”

Applies when
Each proposed VM deployment package.
Responsible role
VibePackr test owner
Before starting
The default deployment completed and supported SSH access is authorized.
Procedure
Plan an SSH connection through the documented customer route and record the exact VM reached.
Expected observation
The authorized tester can open an SSH session to the intended deployed VM.
Keep as evidence
Redacted connection result bound to deployment identity and access route.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

Related VibePackr guidance

TEST-34Verify license metadata in the SSH session

Source locator: “Test the license key in an SSH session:”

Applies when
Each proposed VM deployment package.
Responsible role
VibePackr test owner
Before starting
The authorized tester has an SSH session to the intended VM and the expected license reference.
Procedure
Plan the official read-only license metadata check at the instance licenses endpoint, using the Metadata-Flavor: Google header, and compare the returned license reference with the expected delivery license.
Expected observation
The response identifies the intended license association; an empty or mismatched result is retained as a finding.
Keep as evidence
Redacted command/result record, VM identity and expected license reference.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-35Verify loaded application information

Source locator: “Application info is loaded.”

Applies when
Each proposed VM deployment package.
Responsible role
VibePackr test owner
Before starting
The default deployment completed and its expected application information is identified.
Procedure
Check the post-deployment application information shown to the customer and compare it with the intended product and deployment.
Expected observation
Application information loads and identifies the correct deployed product.
Keep as evidence
Application-information capture and deployment identity.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-36Verify the applicable administrator login
Conditional requirementOfficial source ↗Item link

Source locator: “If the application has admin URL, log into the Admin console with the username/password.”

Applies when
When the application exposes an administrator URL.
Responsible role
VibePackr test owner
Before starting
The exact delivery has a supported first-customer access and credential route.
Procedure
Record the administrator URL and approved authentication route; plan the login test using that route. The source describes username/password; if the product uses another mechanism, obtain Partner Engineer applicability confirmation instead of inventing passwords.
Expected observation
An authorized first customer can reach and use the intended Admin console, or the unresolved route/applicability remains explicit.
Keep as evidence
Redacted login result, access procedure and any Partner Engineer applicability decision.

Current evidence note: Frozen r232 first-customer bootstrap remains blocked at C7. Local repaired Admin candidate evidence is a separate scope and is not substituted for this result.

Related VibePackr guidance

TEST-37Verify specified ports after deployment

Source locator: “Check that the specified ports are opened.”

Applies when
Each proposed VM deployment package.
Responsible role
VibePackr test owner
Before starting
The declared port inventory and separately authorized network observation scope are available.
Procedure
Plan a comparison of observed port exposure with the documented specified ports after deployment, retaining the network context.
Expected observation
Specified ports are open in the expected scope, with unexpected results recorded.
Keep as evidence
Port observation record, source/destination context and comparison to the declared configuration.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-38Repeat the deployment checks across instance sizes

Source locator: “Repeat above steps for different instance sizes (especially large and small) and regions.”

Applies when
Each proposed VM deployment package.
Responsible role
VibePackr test owner
Before starting
The product owner and Partner Engineer establish supported small and large instance test choices.
Procedure
Include different instance sizes, especially small and large, in the matrix and repeat the applicable deployment checks for each.
Expected observation
Each selected size has its own deployment and post-deployment result; untested sizes are visible.
Keep as evidence
Size matrix with configuration, delivery identity, per-check results and exclusions.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-39Repeat the deployment checks across regions

Source locator: “Repeat above steps for different instance sizes (especially large and small) and regions.”

Applies when
Each proposed VM deployment package.
Responsible role
VibePackr test owner
Before starting
Supported regions and the authorized test matrix are agreed.
Procedure
Include multiple agreed regions and repeat the applicable deployment checks in each; record the exact region and zone.
Expected observation
Each selected region has a traceable result; a single-region result is not presented as all-region proof.
Keep as evidence
Region/zone matrix with delivery identity, configuration, per-check results and exclusions.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-40Repeat checks on cloned instances

Source locator: “Repeat the above steps with cloned instances (cloned hard drives).”

Applies when
Each proposed VM deployment package.
Responsible role
VibePackr test owner
Before starting
A supported cloning route, test scope and cleanup disposition are agreed.
Procedure
Add cloned instances or cloned hard drives to the plan and repeat the applicable deployment-flow checks against their recorded lineage.
Expected observation
The cloned-instance path has its own results; original-instance proof is not reused as clone proof.
Keep as evidence
Original-to-clone identity mapping, per-check results and cleanup disposition.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

TEST-41Test every documented post-deployment step
Conditional requirementOfficial source ↗Item link

Source locator: “then you must also test these steps”

Applies when
When the Getting Started guide specifies post-deployment next steps.
Responsible role
VibePackr test owner
Before starting
The delivery-bound Getting Started revision and post-deployment step inventory are identified.
Procedure
Map every documented post-deployment step to an authorized test and record its actual result, including required AI, storage, administrator and health steps when present.
Expected observation
All applicable next steps are tested so successful deployment completion is supported; untested steps remain pending.
Keep as evidence
Guide-step-to-result crosswalk with exact delivery and document revision, outputs and unresolved findings.

Current evidence note: The public guide identifies pending customer AI, storage and administrator boundaries. Recorded local demonstrations do not establish completion of those steps on the review delivery.

Related VibePackr guidance

06 · Component review, final review and publication

26 mapped items. A row’s presence records document coverage only.

SUB-01Reconcile listing prerequisites

Source locator: “reviewed and met all the requirements for listing your product.”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
The current official listing-requirements inventory and exact product are identified.
Procedure
Review the listing prerequisite mapping and request evidence for each applicable requirement; unresolved rows remain pending before submission.
Expected observation
The listing prerequisite set has itemized evidence and an accountable disposition for every applicable requirement.
Keep as evidence
Completed prerequisite crosswalk, supporting private evidence references and unresolved items.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-02Reconcile packaging prerequisites

Source locator: “reviewed and met all the requirements for packaging your product.”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
The current official packaging-requirements inventory and exact image/package are identified.
Procedure
Review the packaging prerequisite mapping against the exact image and deployment package; do not use documentation existence as package compliance evidence.
Expected observation
Every applicable packaging requirement has a delivery-bound result or explicit unresolved disposition.
Keep as evidence
Packaging crosswalk, exact image/package identities and private verification references.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-03Confirm payment setup

Source locator: “Configure payments so that you can be paid for your product's usage.”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr commercial owner
Before starting
The authorized commercial owner and payments configuration scope are identified.
Procedure
Request the commercial owner's confirmation that the required payment setup is complete for the product and legal entity. Keep financial and account data in private records.
Expected observation
The submission has an owner-confirmed payment setup record, with unresolved items visible.
Keep as evidence
Private setup completion reference, legal-entity/product association and commercial owner confirmation.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-04Reconcile end-to-end results before submission

Source locator: “Test your product end-to-end.”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
The exact delivery, authorized test matrix and recorded results are available.
Procedure
Review every applicable preview, listing, deployment and post-deployment row before submission. Keep unsuccessful, not-run and inapplicable cases distinct.
Expected observation
The end-to-end submission record reflects actual results, not a documentation completion score.
Keep as evidence
Delivery-bound test matrix, unresolved findings and owner decisions for exclusions.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-05Obtain the Product Details component review
Explicit requirementOfficial source ↗Item link

Source locator: “Product details”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
The intended Product Details revision and its prerequisite records are identified.
Procedure
Include Product Details in the component-review checklist and retain the corresponding Producer Portal result before publication.
Expected observation
The exact component revision has a traceable review state; submission and approval are recorded separately.
Keep as evidence
Portal component name, revision, state, date and any required changes.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-06Obtain the Pricing component review
Explicit requirementOfficial source ↗Item link

Source locator: “Pricing”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
The intended Pricing revision and its prerequisite records are identified.
Procedure
Include Pricing in the component-review checklist and retain the corresponding Producer Portal result before publication.
Expected observation
The exact component revision has a traceable review state; submission and approval are recorded separately.
Keep as evidence
Portal component name, revision, state, date and any required changes.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-07Obtain the Deployment Package component review
Explicit requirementOfficial source ↗Item link

Source locator: “Deployment package”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
The intended Deployment Package revision and its prerequisite records are identified.
Procedure
Include Deployment Package in the component-review checklist and retain the corresponding Producer Portal result before publication.
Expected observation
The exact component revision has a traceable review state; submission and approval are recorded separately.
Keep as evidence
Portal component name, revision, state, date and any required changes.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-08Track component reviews independently

Source locator: “You can submit the following reviews in any order”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
The Product Details, Pricing and Deployment Package review rows are present.
Procedure
Plan component reviews in the order appropriate for their readiness, while tracking each state separately. Do not treat one completed review as completion of the other components.
Expected observation
The review tracker permits independent ordering and identifies which component reviews remain open.
Keep as evidence
Component review tracker with independent states, revisions and next actions.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-09Track Google installation verification

Source locator: “verifying that your image deploys and uninstalls successfully”

Applies when
Every proposed VM product submission.
Responsible role
Google Cloud Marketplace review team
Before starting
The exact submitted image and Google review record are identified.
Procedure
Reserve a field for Google's image deployment verification result and follow up on any findings through the review coordinator. Vendor tests do not substitute for this Google-owned activity.
Expected observation
Google's image deployment verification outcome and any requested changes are traceable to the submitted image.
Keep as evidence
Google review outcome or correspondence reference, image identity and finding disposition.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-10Track Google uninstallation verification

Source locator: “verifying that your image deploys and uninstalls successfully”

Applies when
Every proposed VM product submission.
Responsible role
Google Cloud Marketplace review team
Before starting
The exact submitted image and Google review record are identified.
Procedure
Reserve a field for Google's image uninstallation verification result and follow up on any findings through the review coordinator. Vendor tests do not substitute for this Google-owned activity.
Expected observation
Google's image uninstallation verification outcome and any requested changes are traceable to the submitted image.
Keep as evidence
Google review outcome or correspondence reference, image identity and finding disposition.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-11Track Google unit testing

Source locator: “running unit tests”

Applies when
Every proposed VM product submission.
Responsible role
Google Cloud Marketplace review team
Before starting
The exact submitted image and Google review record are identified.
Procedure
Reserve a field for Google's unit testing result and follow up on any findings through the review coordinator. Vendor tests do not substitute for this Google-owned activity.
Expected observation
Google's unit testing outcome and any requested changes are traceable to the submitted image.
Keep as evidence
Google review outcome or correspondence reference, image identity and finding disposition.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-12Track Google vulnerability scanning

Source locator: “scanning your VM image for vulnerabilities”

Applies when
Every proposed VM product submission.
Responsible role
Google Cloud Marketplace review team
Before starting
The exact submitted image and Google review record are identified.
Procedure
Reserve a field for Google's VM image vulnerability scanning result and follow up on any findings through the review coordinator. Vendor tests do not substitute for this Google-owned activity.
Expected observation
Google's VM image vulnerability scanning outcome and any requested changes are traceable to the submitted image.
Keep as evidence
Google review outcome or correspondence reference, image identity and finding disposition.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-13Track automatic validation after package upload

Source locator: “after you upload it”

Applies when
Every proposed VM product submission.
Responsible role
Google Cloud Marketplace validation service
Before starting
The exact uploaded package revision is identified.
Procedure
Record the portal result of the automatic deployment-package validation triggered by upload. Keep uploading and successful validation as separate states.
Expected observation
The upload has a corresponding automatic validation result for the same package.
Keep as evidence
Upload record, package identity and automatic validation state.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-14Track validation for every package update

Source locator: “each time that you make a subsequent update to the package.”

Applies when
Whenever the deployment package is updated.
Responsible role
Google Cloud Marketplace validation service
Before starting
The prior and updated package revisions are identified.
Procedure
Record the automatic validation result for each subsequent package update; do not carry a prior revision's success into the updated revision.
Expected observation
Every updated revision has its own validation result.
Keep as evidence
Revision history, update identity and per-revision validation states.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-15Confirm portal completion after package validation

Source locator: “it marks this review as complete in Producer Portal.”

Applies when
Every proposed VM product submission.
Responsible role
Google Cloud Marketplace validation service
Before starting
Successful validation of the current package is evidenced.
Procedure
Check the Deployment Package review state that Producer Portal marks complete after successful validation; retain its exact revision.
Expected observation
The portal completion state corresponds to successful validation of the intended current package.
Keep as evidence
Portal completion capture and matching validation/package identity.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-16Test after package validation and before publication submission

Source locator: “thoroughly test your product after validation is complete”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
The current package validation is complete and its identity is fixed.
Procedure
Schedule thorough product tests after validation and before submitting for publication, and bind the results to that validated revision.
Expected observation
The post-validation test results apply to the package being submitted for publication.
Keep as evidence
Validated package identity, dated test matrix and recorded results before publication submission.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-17Gate private publication on component approvals
Explicit requirementOfficial source ↗Item link

Source locator: “After Google has approved your product's component reviews”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
All component-review states and exact revisions are available.
Procedure
Check that Google has approved the product component reviews before the coordinator plans private publication for final testing and review.
Expected observation
Private publication is gated by the required component approvals, with unresolved reviews visible.
Keep as evidence
Component approval references, revision binding and private-publication readiness decision.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-18Plan private Publish for Google final review

Source locator: “Click Publish. This notifies Google that your product is ready for final review before publication.”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
Google component approvals and separately authorized submission action are recorded.
Procedure
In the authorized submission procedure, open the product Overview in Producer Portal and select Publish to notify Google for final testing and review. Record this as private publication, not public launch.
Expected observation
Google is notified for final review and the product is privately published for that stage.
Keep as evidence
Private Publish confirmation, date, delivery identity and Google final-review reference.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-19Identify the review affected by a requested change
Conditional requirementOfficial source ↗Item link

Source locator: “Navigate to the page you'd like to make changes to.”

Applies when
When a product mistake is found or Google requests a change after submission.
Responsible role
VibePackr review coordinator
Before starting
The requested change, relevant page and submitted revision are identified.
Procedure
Record the correction request and identify the exact product page and component review affected before planning the change.
Expected observation
Each requested change has an identified target and affected review.
Keep as evidence
Change request, page/component mapping and prior submitted revision.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-20Acknowledge the resubmission consequence
Conditional requirementOfficial source ↗Item link

Source locator: “Click Acknowledge to acknowledge that you must re-submit the corresponding review”

Applies when
When changing a product page after submission.
Responsible role
VibePackr review coordinator
Before starting
The affected review and authorized change scope are identified.
Procedure
Include the Acknowledge step in the change procedure so the owner explicitly accepts that the corresponding review must be resubmitted.
Expected observation
The change record shows acknowledgment of the required resubmission.
Keep as evidence
Acknowledgment record and affected review identity.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-21Record the intended post-submission changes
Conditional requirementOfficial source ↗Item link

Source locator: “Make any intended changes to your product.”

Applies when
When an authorized post-submission correction is needed.
Responsible role
VibePackr review coordinator
Before starting
The exact requested change and corresponding review are identified and acknowledged.
Procedure
Have the responsible owner apply only the intended correction through the approved change procedure; preserve before/after revision identities in the review record.
Expected observation
The changed revision corresponds to the intended correction and its scope is reviewable.
Keep as evidence
Change summary, before/after identities and owner authorization reference.

Current evidence note: This is a review-process checklist. It does not authorize changes to the frozen Golden or product artifacts.

SUB-22Resubmit the affected component review
Conditional requirementOfficial source ↗Item link

Source locator: “Re-submit the affected review for approval.”

Applies when
After an acknowledged post-submission change.
Responsible role
VibePackr review coordinator
Before starting
The changed revision and affected review are recorded.
Procedure
Include resubmission of the affected review in the authorized submission plan and retain the new approval result separately from the previous revision.
Expected observation
The updated revision has a resubmission record and its own review disposition.
Keep as evidence
Resubmission reference, changed revision, review outcome and remaining feedback.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-23Gate public launch on all review approvals
Explicit requirementOfficial source ↗Item link

Source locator: “After all reviews have been approved”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
Component and final-review results for the exact intended delivery are available.
Procedure
Verify all review approvals before planning public launch; private publication and document completion do not satisfy this gate.
Expected observation
The public-launch checklist has complete review approval references for the intended delivery.
Keep as evidence
All-review approval matrix, final-review outcome and delivery identity.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-24Plan Enable public display

Source locator: “Click Enable public display.”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
All reviews are approved and the product owner authorizes public launch separately.
Procedure
In the authorized launch procedure, open the product Overview in Producer Portal and select Enable public display.
Expected observation
The portal presents the next public-launch confirmation for the approved product.
Keep as evidence
Portal action record tied to the approved delivery and launch authorization.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-25Resolve a missing Enable public display control
Conditional requirementOfficial source ↗Item link

Source locator: “If you don't see this button, verify that you've published your product privately.”

Applies when
When Enable public display is not visible.
Responsible role
VibePackr review coordinator
Before starting
The product Overview and current publication state are known.
Procedure
Check the private-publication record first and route any remaining portal-state mismatch to the review coordinator or Partner Engineer; do not infer public readiness from a missing control.
Expected observation
The missing-control finding is tied to the actual private-publication state and an explicit next action.
Keep as evidence
Portal state capture, private Publish record and any clarification.

Current evidence note: Not yet evidenced for the exact Marketplace review delivery.

SUB-26Record the final Make public action

Source locator: “Click Make public.”

Applies when
Every proposed VM product submission.
Responsible role
VibePackr review coordinator
Before starting
All reviews are approved, private review is complete and the exact public launch is authorized.
Procedure
Include Make public as the final authorized portal action after Enable public display; verify and record the resulting public listing instead of assuming the action alone proves availability.
Expected observation
The approved product is publicly visible and the actual publication state is recorded.
Keep as evidence
Make public confirmation, public listing URL, observed visibility, timestamp and delivery identity.

Current evidence note: Public website documentation is available. This is not evidence that the Marketplace product has been approved or made public.

Source scope and remaining dependencies

Five official pages checked 2026-10-04. Read their scope and revision dates. Linked specialized policies and deployment instructions still need their responsible owner’s assessment. Private or newly issued Google requirements belong in the workbook’s additional-requirements section.

Some official pages retain legacy tools or version wording. Record the stated requirement and obtain the current supported procedure from the assigned Partner Engineer. This guide does not authorize a legacy deletion recipe, a new privilege grant, or rebuilding the frozen image.